Latest CVE Feed
-
4.3
MEDIUMCVE-2021-1562
A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive information on an affected system. This vulnerability is due to improper input validation and authorizati... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-3005
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.... Read more
Affected Products : mk-auth- Published: Jan. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32522
Missing Authorization vulnerability in Jaed Mosharraf & Pluginbazar Team Open Close WooCommerce Store.This issue affects Open Close WooCommerce Store: from n/a through 4.9.1. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12431
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.... Read more
Affected Products : gitlab- Published: Jan. 08, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-4036
The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and pa... Read more
Affected Products : simple_blog_card- Published: Aug. 30, 2023
- Modified: May. 02, 2025
-
4.3
MEDIUMCVE-2024-34453
TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).... Read more
Affected Products :- Published: May. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-5118
Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."... Read more
Affected Products : java_system_identity_manager- Published: Nov. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-2786
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands. ... Read more
- Published: Jun. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-22401
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Gu... Read more
- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4934
Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.... Read more
Affected Products : online_photo_pro- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-10104
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a ... Read more
Affected Products : zammad- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2947
Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network acc... Read more
Affected Products : peoplesoft_enterprise_human_capital_management_absence_management- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-4823
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.... Read more
Affected Products : cpanel- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3529
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message par... Read more
- Published: May. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-4931
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible ... Read more
Affected Products : backupwordpress- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-1377
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.... Read more
- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-49287
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Feed for WooCommerce: from n/a through 2.2.8.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2012-6316
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to us... Read more
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-4661
Multiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted ZIP file that is not properly handled when the victim uses the (1) Update or (2) Plug-In co... Read more
Affected Products : bigant_server- Published: Mar. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9517
Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to vb.htm.... Read more
- Published: Jan. 05, 2015
- Modified: Apr. 12, 2025